Figure 36-7 – H3C Technologies H3C WX6000 Series Access Controllers User Manual

Page 406

Advertising
background image

36-10

Figure 36-7 Portal service application

Table 36-2

describes the portal service configuration items.

Table 36-2 Portal service configuration items

Item

Description

Interface

Specify the interface to be enabled with portal authentication.

Portal Server

Specify the portal server to be applied on the specified interface. Options include:

Select Server: Select an existing portal server from the portal server drop-down list.

New Server: If you select this option from the drop-down list, the portal server configuration
area, as shown in

Figure 36-8

, will be displayed at the lower part of the page. You can add

a portal server and apply the portal server to the interface. For detailed configuration, refer
to

Table 36-3

.

Enable Local Server: If you select this option from the drop-down list, the local portal
service configuration area, as shown in

Figure 36-9

, will be displayed at the lower part of

the page. You can configure the parameters for local portal service. For detailed
configuration, refer to

Table 36-4

.

Method

Specify the portal authentication mode, which can be:

Direct: Direct portal authentication.

Layer3: Layer 3 portal authentication.

Re-DHCP: Re-DHCP portal authentication.

In Layer-3 portal authentication mode, Layer 3 forwarding devices are not required to be
present between the authentication client and the access device. However, if they are
present, you must select the Layer 3 portal authentication mode.

In Re-DHCP portal authentication mode, a client is allowed to send out packets using a
public IP address before it passes portal authentication. However, responses of the
packets are restricted.

If the local portal server is used, you can configure the re-DHCP mode but it will not take
effect.

Auth Network
IP

Network Mask

Specify the IP address and mask of the authentication subnet for Layer 3 portal authentication.

By configuring an authentication subnet, you can specify that only packets from users on the
authentication subnet trigger portal authentication. Packets that are neither from portal-free
users nor from the authentication subnet will be discarded.

You can configure an authentication subnet only when the Layer 3 portal authentication mode
is used.

The authentication subnet in direct mode is any source IP address, and that in re-DHCP mode
is the private subnet to which the interface’s private IP address belongs.

Advertising